XK0-006 Security Practice Question
A Linux administrator needs to configure a system to use a central authentication service. The service requires that user credentials are sent over the network in an encrypted format and that the client validates the server's certificate. Which of the following should the administrator configure?
⚠ Common exam trap
A common mix-up: candidates confuse encryption with certificate validation; some options encrypt traffic but do not verify the server's identity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure LDAP with TLS using the ldaps:// URI and set TLS_REQCERT to demand in /etc/ldap/ldap.conf.
LDAP with TLS (LDAPS) encrypts authentication traffic, and setting TLS_REQCERT to demand ensures the client validates the server's certificate. This combination meets both the encryption and validation requirements. The other options either lack certificate validation or use insecure protocols.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure Kerberos with a keytab file and set the default realm in /etc/krb5.conf.
Why it's wrong here
Kerberos provides strong authentication and can encrypt tickets, but it does not inherently validate server certificates in the same way TLS does. The keytab file is used for service authentication, not for client-side certificate validation. This option does not explicitly address certificate validation and may not encrypt all credential exchanges depending on the setup.
- ✗
Configure NIS with a secured map and use ypbind with a password.
Why it's wrong here
NIS is an outdated and insecure protocol that does not encrypt authentication traffic by default. Even with a 'secured' map, it lacks modern encryption and certificate validation. This does not meet the requirements for encrypted credentials and server certificate validation. NIS should be avoided in favor of more secure alternatives.
- ✗
Configure SSSD with ldap_id_use_start_tls = true and ldap_tls_reqcert = never.
Why it's wrong here
Setting ldap_tls_reqcert = never disables certificate validation, which violates the requirement to validate the server's certificate. While start_tls encrypts the connection, the lack of certificate validation makes it vulnerable to man-in-the-middle attacks. This configuration does not meet the security requirements.
- ✓
Configure LDAP with TLS using the ldaps:// URI and set TLS_REQCERT to demand in /etc/ldap/ldap.conf.
Why this is correct
Using LDAPS (LDAP over TLS) encrypts the authentication traffic. Setting TLS_REQCERT to demand enforces certificate validation, ensuring the client verifies the server's certificate. This meets both the encryption and validation requirements. It is a standard way to secure LDAP communications.
Go deeper
Related to this question
Learn chapter
User and Group Administration
Key term
Linux
Linux is an open-source operating system that manages computer hardware and software, widely used in servers, desktops, and embedded systems.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.